Bugzilla – Bug 1101689
VUL-1: CVE-2018-1333: apache2: HTTP/2 DoS
Last modified: 2021-01-12 12:15:12 UTC
CVE-2018-1333 Description: By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Credit: The issue was discovered by Craig Young of Tripwire VERT. References: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1333 http://seclists.org/oss-sec/2018/q3/39
Packages submitted.
For: 15/apache2 and 12/apache2.
SUSE-SU-2018:2336-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1101689 CVE References: CVE-2018-1333 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): apache2-2.4.23-29.21.1 SUSE Linux Enterprise Server 12-SP3 (src): apache2-2.4.23-29.21.1
openSUSE-SU-2018:2397-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1101689 CVE References: CVE-2018-1333 Sources used: openSUSE Leap 42.3 (src): apache2-2.4.23-25.1
SUSE-SU-2018:2424-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1101688,1101689 CVE References: CVE-2018-1333,CVE-2018-8011 Sources used: SUSE Linux Enterprise Module for Server Applications 15 (src): apache2-2.4.33-3.3.1
openSUSE-SU-2018:2433-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1101688,1101689 CVE References: CVE-2018-1333,CVE-2018-8011 Sources used: openSUSE Leap 15.0 (src): apache2-2.4.33-lp150.2.3.1
done